Feds Trying To Get Master Encryption Keys From Tech Companies

from the of-course-they-are dept

This is hardly surprising, but Declan McCullagh is reporting that the feds have been trying to get various tech companies to hand over their master encryption keys so that the NSA and FBI can decrypt any of the messages they scoop up. So far the tech companies have been resisting:

"The government is definitely demanding SSL keys from providers," said one person who has responded to government attempts to obtain encryption keys. The source spoke with CNET on condition of anonymity.

The person said that large Internet companies have resisted the requests on the grounds that they go beyond what the law permits, but voiced concern that smaller companies without well-staffed legal departments might be less willing to put up a fight. "I believe the government is beating up on the little guys," the person said. "The government's view is that anything we can think of, we can compel you to do."

It's unclear from the article if any companies have given in and provided the keys, but it sounds like at least most of the big ones are fighting it. Microsoft and Google both directly denied that they would hand over such a master key. Lots of other companies didn't respond to Declan's questions. Of course, it's no surprise that the government would ask. They've been asking for access and backdoors to just about everything.

If they can't convince the companies that this is legal and required, you can fully expect that a law will be proposed shortly which will more or less require companies to hand over such keys.

"The requests are coming because the Internet is very rapidly changing to an encrypted model," a former Justice Department official said. "SSL has really impacted the capability of U.S. law enforcement. They're now going to the ultimate application layer provider."

Once again, perhaps it's time to think about moving away from a situation in which all our "cloud" data is stored in a few centralized spots. You can still get the benefits of a cloud, even if you control the data yourself -- if only companies would open up and allow users to point their services at data stored elsewhere.

Re:

They're not simply out of control, they've gone stark raving mad. "Give us your encryption keys because we said so." How about no.

Wonder what will happen with all those Kickstarter projects and whatnot that are attempting to encrypt data/communication. If they don't cave to the government's (UNCONSTITUTIONAL) demands, the latter will likely falsely accuse them of aiding the enemy, because they're lunatics.

so, surely the answer then is for all the companies concerned to have a united front and help each other, isn't it? look at what the entertainment industries achieve, just because they can draw on resources from near and far. it's no good the 'big boys' being able to resist if the 'little guys' cant. all that will lead to is courts using the defeat of the little guys as precedent to get the 'big guys' to confirm. dont take a surgeon to know the way to go on this, does it?

Not that we'd care

Like just open up all the channels and have done with it. Of course the Internet is a tameable beast, so they have to have all the keys to it.

If they get them, I'm off forever. If you can't be secure at all with any of it, why bother?

The SSL keys are the only thing stopping the NSA from having real-time spying on-line, and it's only a matter of time before these companies give in because they're gutless cowards, just like everyone who doesn't care.

It might not be surprising to some people but it is highly disturbing to me, and I'm pretty much convinced that the end is near for that 'wild west' synergy that used to be so true on the Internet.

It'll be owned and controlled by the corporate masters and watched every second by the NSA. Nothing will be private, nothing will be secure.

We're half-way there now. I can see the writing all over the wall-ten feet high.

Why is the net pursuing encryption?

The trend towards encryption on the net is driven by the fact that it makes us safer. We can trust what we read, who we are talking to, that our private matters, like credit cards and youthful indiscretions, remain so.

The monetary rewards for stealing our private actions is large. Most elected now have used data mining and demographic analysis to get elected - they think they need to keep lying and stealing to stay in office.

The nation needs ambiguity and privacy. It need transparancy, so we can see what our tax dollar buys us. The consent of the justly governed is an informed consent.

This is simply insane

The direct analogy of this is that you must give the keys to your house to any officer or federal agent that demands them from you.
Sad state this country is in. This all started with Bush and Obummer is just taking it to the next level. Makes me sick.

sigh

Plausible deniability

I don't believe them: I trust everything that Google, Apple, Yahoo and Microsoft say the same way I trust everything the government says.

There is an encryption technology called plausible deniability: dual encrypted channels with double keys. When the government demands the keys, you give them one set of keys to placate them so you don't end up in jail. I won't bore you with the details, but check out True Crypt.

I never liked the idea of storing anything of mine on rack servers (AKA the cloud) owned by anyone other than me. All the B.S. about we protect you is utter nonsense. I'm going back to type writers, in person face to face communications, and when I do use skynet, I'll encrypt my messages on top of the SSL layer. Then I'll use TOR because I don't even want anyone knowing where I'm sending messages to in the first place. If they want to track me, they can use old fashioned detective work.

And this is why RMS warded against cloud compution: You have the same lack of control as propritary software, in this case even less since at least you can perma delete in windows while online the goverment can easliy get it without you knowing and any "delete" function may just make it unaccessable to you.

quick on the heels of...

So, they just had their shill Snowden do the leak to test the waters. They didn't a massive shit storm, just a minor squall. They give it a small amount of time and then hit us with this gem. Their plan is working perfectly. MUAaaahhhh ha ha ha haaaa!

Re: quick on the heels of...

Public Key Encryption 101

What would help even more is if there was some way to get people to take encryption seriously, and not just as a checkbox or prepending https to a url.

The notion of "trust" is absolutely core to the security of public key encryption. You need to determine whether a key you are using was actually issued by who you think it was issued by.

We now know that the default way this is "ensured", that it was vouched for by a CA such as Verisign, Microsoft, etc., is meaningless in terms of being able to trust the key. People have to start taking a more active role in verifying the keys they use.

A new law ?

"you can fully expect that a law will be proposed shortly which will more or less require companies to hand over such keys". I doubt it. Too difficult to sneak something like that by right now. They'll just go to the FISA court and get it to interpret some existing law in a way that allows them to demand what they want.

The gate keepers

After further consideration, I come to the conclusion that all the mentioned companies will gladly hand over the keys. I repeat, they will gladly hand over the keys because the government has stuff they want! Data! Yes, Quid pro quo. I'm sure that since the NSA is acting as the gate keeper of all this meta data, they are liberally sharing stats and other information with their partners. Of course they're lying to all their partners about it telling each one that they aren't sharing their data with the competition.

Imagine the NSA telling Microsoft there is an exploit in the OS long before anyone is publically aware of it. The NSA will tell them about it and ask them not to patch it yet. This way, the NSA can exploit it themselves. Microsoft can start fixing it so when the vulnerability goes public, Microsoft can have a patch ready to go. Ditto with all the viruses. I wonder how many viruses are military in nature?

I imagine there is a whole lot of information sharing going on we have not learned about yet. The NSA, being the gate keepers keeping big tech in check.